Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2024-11198
Disclosure Date: November 19, 2024 (last updated November 20, 2024)
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-38709
Disclosure Date: July 12, 2024 (last updated July 13, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Milan Petrovic GD Rating System allows PHP Local File Inclusion.This issue affects GD Rating System: from n/a through 3.6.
0
Attacker Value
Unknown
CVE-2024-25093
Disclosure Date: February 29, 2024 (last updated January 17, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Rating System allows Stored XSS.This issue affects GD Rating System: from n/a through 3.5.
0
Attacker Value
Unknown
CVE-2017-18591
Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
0
Attacker Value
Unknown
CVE-2018-5292
Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
0
Attacker Value
Unknown
CVE-2018-5293
Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
0
Attacker Value
Unknown
CVE-2018-5289
Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
0
Attacker Value
Unknown
CVE-2018-5288
Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
0
Attacker Value
Unknown
CVE-2018-5287
Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
0
Attacker Value
Unknown
CVE-2018-5290
Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
0